R E L A T E D   C O N T E N T

Free email newsletters




ADVERTISEMENT

Phreak-out over VoIP

Users will get ripped off if operators don't implement encryption, warns industry specialist

Clive Akass, Personal Computer World 16 May 2008
ADVERTISEMENT

Phreaking, the hacking of telephone systems, has entered the VoIP age and could become a big problem unless operators tighten up their security, according to a VoIP specialist.

Hacking phones became something of a cult activity in the 1970s after youngsters – including Steve Wozniac, who built the first Apple computers – discovered that tones pitched at certain frequencies could open lines for free calls.

Hackers tended to present phreaking as a victimless crime because nobody lost any actual money, though operators were deprived of the cost of the calls.

But phreaking's latest incarnation could put VoIP users out of pocket, warns Dave Gladwin, vice-president of products at Newport Networks.

The reason is that VoIP services such as BT's Broadband Talk provide access to paid-for calls, too.

"Actually I like Broadband Talk. It is very useful and basically turns my notebook into a phone," Gladwin says. "I can sit in a hotel room abroad and receive or make calls as if I am at home."

But when those calls are made to landlines or mobiles they have to be paid for. And Gladwin claims that VoIP log-in details are on sale on the web at prices higher than those charged for credit-card details.

Log-in details are relatively easy to harvest at public hotspots because, according to Gladwin, nine out of 10 VoIP providers using the standard SIP protocol do not support encryption. Skype users are not affected because that system uses its own protocols and does encrypt traffic.

Gladwin points out that knowledgeable users will always check that they are on a secure link if they are making an online transaction, but "they don't tend to think about it when they are making an VoIP call".

The trouble is that VoIP operators need to implement encryption – users cannot do it on their own. "At the moment there is no call for them to do it. Encryption will require some investment. They will only spend the money if there is a demand for it," said Gladwin.


All Online
Tags: Voip, Bt, Phreaking

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story
R E A D E R   C O M M E N T S

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Computer People
SQL Server 2008 Developer – Staffordshire – Market Rate – 3 - 6 month initial role Computer People have an exciting opportunity for a SQL Server 2008 Developer within an Large organisation based in Staffordshire. ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
JAVA J2SE DEVELOPER – CREDIT DERIVATIVES amp; Credit Derivatives (CDS, CDO, CDX, IRD, IRS), Exotics and Structured Hybrid products. Technical skills include: Server side Java, SQL, Sybase, SOAP, WEB SERVICE and OOA/D. Nice to have ... more >
| Aston Carter
Java, C++, SQL Analyst Developer – Interest Rate Risk Java, C++, SQL, Analyst Developer, interest rate, risk, credit risk, market risk, perl, scripting • At least 2-5 years experience developing in C++ and Java • ... more >
More job opportunities